CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Webtoffee 1Import Export Wordpress Users Jul 9, 2025 Mar 22, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attack...Show more |
1Webtoffee 1Import Export Wordpress Users Jul 9, 2025 Mar 22, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6....Show more |
1Webtoffee 1Import Export Wordpress Users Jul 9, 2025 Mar 22, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter. This...Show more |
1Webtoffee 1Import Export Wordpress Users Jul 9, 2025 Mar 22, 2025 N/A· v4 7.6 HIGH· v3 N/A· v2 The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function. This makes it possible for authent...Show more |
1Webtoffee 1Import Export Wordpress Users Apr 8, 2026 Jan 11, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8...Show more |
1Webtoffee 1Import Export Wordpress Users Apr 8, 2026 Jul 18, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versio...Show more |
1Webtoffee 1Import Export Wordpress Users Nov 21, 2024 Apr 23, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV. |
1Webtoffee 1Import Export Wordpress Users Nov 21, 2024 Aug 23, 2019 N/A· v4 7.3 HIGH· v3 6.0 MEDIUM· v2 The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by th...Show more |